Closing Renovate's transitive-CVE blind spot
Renovate's vulnerability alerts only cover direct dependencies in npm and pip. Here is the CI-gate and manual-remediation pattern that catches the rest, and why I run Renovate without Dependabot.
Development#security#supply-chain#renovate